Security Sweep — Public Repository & alai.no Hardening (MC #107285)

Security Sweep — Public Repository & alai.no Hardening (MC #107285)

Date: 2026-08-16
Scope: johnatbasicas/alai-web, https://alai.no, and https://ucenje.alai.no
Production commit: 620dd3af082952b7dbded28a4c5b4685b5445366
Pull request: johnatbasicas/alai-web#2

Trigger

The source repository was public and exposed tracked CLAUDE.md and .claude/** files. A full sweep was ordered to identify and remove repository, deployment, secret-handling, browser, and production exposure risks.

Confirmed findings

  1. Public GitHub access exposed agent metadata and internal operational instructions.
  2. A stale index.html.bak file was publicly readable on alai.no.
  3. A hidden internal .credits.md file was publicly readable on ucenje.alai.no.
  4. Deprecated Vercel state contained expired OIDC tokens and duplicate local backups.
  5. A legacy unused mail dependency had high-severity advisories.
  6. GitHub Actions used mutable action tags; repository secret scanning and branch protection were unavailable or disabled.
  7. Pages lacked a true 404 response and a complete Content Security Policy.
  8. The contact proxy lacked bounded streaming input, complete validation, honeypot handling, safe upstream errors, and dynamic-response security headers.
  9. The GitHub Cloudflare deploy token was stale, causing repeated authentication failures.
  10. Wrangler debug logs contained local proxy shared-secret material and were too broadly readable.

Remediation completed

Repository and source

Cloudflare Pages

Contact endpoint

CI and credentials

Verification

Evidence

Evidence directories are restricted to user-only access. No credential values are recorded in this page or its evidence summaries.

Residual low risks

  1. GitHub branch protection for a private repository requires a paid plan. Compensating controls are enabled: private visibility, selected SHA-pinned Actions, read-only workflow permissions, Gitleaks CI, web commit signoff, and merged-branch deletion.
  2. DNSSEC and CAA remain separate registrar/certificate-issuer changes and require a dedicated controlled rollout.
  3. The edge tombstone rules should remain until the old one-week cache lifetime has fully elapsed; then revalidate direct paths before considering rule removal.

Closure

Technical remediation and production verification are complete. This page is the task-specific BookStack record for MC #107285.


Revision #1
Created 2026-08-17 11:54:47 UTC by John
Updated 2026-08-17 11:54:47 UTC by John